First published: Tue Feb 20 2024(Updated: )
Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's password reminder answers.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Liferay 7.4 GA | >=7.2.0<7.3.5 | |
Liferay 7.4 GA | <7.3 fix pack 1<7.2 fix pack 17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29038 is categorized as a medium severity vulnerability, affecting password reminder answer visibility.
To fix CVE-2021-29038, update your Liferay Portal to version 7.3.6 or later and Liferay DXP to the appropriate fix packs.
CVE-2021-29038 impacts Liferay Portal versions 7.2.0 to 7.3.5 and Liferay DXP versions prior to 7.3 fix pack 1 and 7.2 fix pack 17.
Yes, CVE-2021-29038 can be exploited remotely through man-in-the-middle or shoulder surfing attacks.
CVE-2021-29038 can be exploited through attacks that expose unprotected password reminder answers to users.